So if I understand GDPR correctly: If I want a service/business to remove all my personal data, they have to comply with it in a certain timespan or get in trouble with the law.

If I understand federation correctly: All posts get replicated on federated instances all over the fediverse.

My question: If I e.g. want lemmy.world to remove my data, all my posts etc are still up on lemmy.ml right? As they just have a copy of these posts?

Would I as a customer have to contact every single instance to get my data removed? Or how does GDPR compliance work with lemmy?

Or am I completely misunderstanding how GDPR works?

  • substill@vlemmy.net
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    1 year ago

    It isn’t a single site or host, and there is no owner. Wouldn’t that be like saying “e-mail must be GDPR compliant”?

    • Firipu@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      1 year ago

      Not as if the GDPR cares about that specifically. Whatever excuse or justification you might have, the law still applies… Mail servers also have to comply with the law.

      • ᗪᗩᗰᑎ@lemmy.ml
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 year ago

        To the point of the person you’re replying to, I think it may be treated the same as email. For example, if you send an email and it gets forwarded somewhere else, all the “custodian of your data” (lets say google in this example) can do is delete any copies they have on their server. Anything outside of that is outside their responsibility/capacity.